Telecom Identity Bridging for Web Application Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing multiple usernames and passwords across disjointed application domains, leading to a cumbersome authentication and authorization process, which discourages users from engaging with telecom-hosted applications as they prefer over-the-top (OTT) services for single-sign-on experiences.
Innovation Solution
A method and system that issue access tokens associated with user identifiers subscribed to telecommunications networks, allowing web-based applications to authenticate and authorize user data access, leveraging OTT proxy elements to bridge user authentication and authorization across internet and telecom domains, utilizing mechanisms like OAuth 2.0 for token-based authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manage multiple usernames and passwords across different application domains, then security and access control are maintained, but user convenience and ease of operation deteriorate
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between users and multiple applications. This intermediary manages credentials centrally and provides delegated authorization, allowing users to authenticate once and access multiple applications without manually managing separate usernames and passwords for each application domain.
Solution Approach 2:
The patent implements a universal authentication mechanism that works across multiple application domains (telecom, enterprise, and Internet domains). This single authentication system provides multi-functional access control, enabling users to authenticate once and gain access to various applications through delegated authorization tokens.
2Reliability
If users log in multiple times each day to different applications, then access control is maintained, but time consumption and productivity worsen
Solution Approach 1:
The patent implements preliminary authentication where users authenticate once in advance to an intermediary system. The system then pre-issues delegated authorization tokens that allow users to access multiple applications without repeating the authentication process, significantly reducing time consumption while maintaining access control.
Solution Approach 2:
The patent enables continuous access to multiple applications through delegated authorization tokens that remain valid across different application domains. This eliminates the need for repeated login actions, allowing users to continuously access services without interruption or time loss.
3Adaptability or versatility
If users enter and manage personal information across all application domains, then data access is enabled, but complexity of information management increases
Solution Approach 1:
The patent extracts personal information management from individual application domains and centralizes it in an intermediary authentication system. Users enter their personal information once with the intermediary, which then manages and secures this data, extracting the burden of information management from users while enabling versatile data access across applications through controlled token issuance.
Data Source
AI summary
Methods, systems, and computer readable media for bridging user authentication, authorization, and access between web-based and telecom domains are disclosed. In one example, a method includes issuing, to an application hosted in a web-based network, an access token associated with a user identifier subscribed to a telecommunications network, wherein the access token is issued in response to receiving telecommunications network credentials from a client device associated with the user identifier and receiving, at an over the top (OTT) proxy element in the telecommunications network from the application, the access token for requesting user data associated with the client device to be used to access the application. The method further includes retrieving the user data if the access token is valid a telecommunications network context condition is met and providing the user data to the application, wherein access to the application by the client device is based on the user data.


